cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
7244
Views
0
Helpful
3
Replies

AnyConnect - No policy server detected

dgaikwad
Level 5
Level 5

Hi Experts,
Going through migration from Cisco NAC Agent to AnyConnect.
Since, we are going location wise, I have called the switch IP address in Client Provisioning policy to do posture check via AnyConnect.
But, the posture check is still happening via NAC Agent and no via AnyConnect, while AnyConnect shows no policy server detected?

1 Accepted Solution

Accepted Solutions

hslai
Cisco Employee
Cisco Employee

When switching from NAC agent to AnyConnect ISE posture, we have to ensure the ISE client provisioning is configured to use AnyConnect.

Please also take a look at ISE Posture Prescriptive Deployment Guide

View solution in original post

3 Replies 3

Mike.Cifelli
VIP Alumni
VIP Alumni
How did you configure your AC profile posture agent settings in ISE? In there you need to specify the ip address of your ISE psn/s under the posture protocol section.

hslai
Cisco Employee
Cisco Employee

When switching from NAC agent to AnyConnect ISE posture, we have to ensure the ISE client provisioning is configured to use AnyConnect.

Please also take a look at ISE Posture Prescriptive Deployment Guide

The issue has been resolved.
We were using 9200 series switch with Denali OS 16.x, this new OS requires the device-tracking policy IPDT_Policy, command applied.
Applying this command resolved the issue.